The issue was addressed with improved checks. This issue is fixed in Safari 18.3, visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. Processing maliciously crafted web content may lead to memory corruption.
CVE ID: CVE-2025-24189
CVSS Base Severity: HIGH
CVSS Base Score: 8.8
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vendor: Apple
Product: visionOS, tvOS, macOS, Safari, watchOS, iOS and iPadOS
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 14.02% (scored less or equal to compared to others)
EPSS Date: 2025-06-16 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: total
SSVC Automatable: false